GHSA-f3h9-8phc-6gvh, CVE-2024-0964
pypi/gradio
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
A local file include could be remotely triggered in Gradio due to a vulnerable user-supplied JSON value in an API request.
All versions before 4.9.0
Upgrade to version 4.9.0 or above.
2024-02-07
source |